CVE-2021-29267: XSS
Published Mar 29, 2021
·Updated
Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature.
Affected Software
1 affected component
SherlockIM SherlockIM<=2021-03-29
Event History
Mar 29, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29267?
CVE-2021-29267 is considered a medium severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2021-29267?
To fix CVE-2021-29267, update SherlockIM to a version released after March 29, 2021, which mitigates the XSS vulnerability.
3
Who is affected by CVE-2021-29267?
Users of SherlockIM versions up to and including 2021-03-29 are affected by CVE-2021-29267.
4
What is the impact of CVE-2021-29267?
The impact of CVE-2021-29267 includes the risk of attackers exploiting the XSS vulnerability to target help-desk staff via the chatbot feature.
5
When was CVE-2021-29267 disclosed?
CVE-2021-29267 was disclosed on March 29, 2021.